styx

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's financial capabilities match its stated BTC→sBTC bridge purpose, but it carries high inherent risk because it can autonomously move funds and depends on a not-fully-verifiable Styx SDK/backend, with evidence of a Vercel-hosted intermediary and a pre-configured API key. This looks more like a risky DeFi transaction skill than confirmed malware.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
Mar 20, 2026, 11:18 PM
Package URL
pkg:socket/skills-sh/aibtcdev%2Fskills%2Fstyx%2F@72c2f0eea8c9a3fb798d84a28fdde632789102ee